Skip to content

Security and reporting

The repository’s SECURITY.md is the canonical security policy. It identifies the supported Alpha line, names the sensitive data that must never enter issues/logs/tests/fixtures/commits, and directs suspected vulnerabilities to GitHub private vulnerability reporting, with a maintainer-email fallback when that route is unavailable.

This page intentionally does not duplicate response-time promises, supported-version commitments, or another reporting channel. Those details belong in the policy so that security reporting has one authoritative source.

Do not open a public issue containing an exploit proof of concept, API hash, phone number, authorization key, session key, bot token, 2FA value, proxy credential, session database, or portable session string. Preserve the minimum evidence needed to reproduce the issue and use the private maintainer route described in the canonical policy.

For operational guidance on protecting session material, encrypted storage, redaction limits, native/fallback boundaries, and Telegram API responsibility, see the security model and Session Security. Those pages explain safe operation; they do not replace the reporting policy.